negqedtua.exe

JNESS Inc.

It runs as a windows Service named “MayaSvc”.
Publisher:
JNESS Inc.  (signed and verified)

Version:
1.0.0.142

MD5:
72a2c38f55c2d8e5684c6bd9aa7c291e

SHA-1:
c377bdb4bed7348a2db38a956e68441fcbd1e7d6

SHA-256:
d68acb5447fcdd245b110e68cb38d44b2ba22e3db205c77d2c7624970fdafb00

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 10:54:49 PM UTC  (today)

File size:
2.8 MB (2,903,440 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\negqedtua.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/21/2016 9:00:00 AM

Valid to:
11/16/2016 8:59:59 AM

Subject:
CN=JNESS Inc., O=JNESS Inc., L=Seongdong-gu, S=Seoul, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
332B8827113AF36FFD1F3293E7F16175

File PE Metadata
Compilation timestamp:
9/20/2016 1:42:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:oO764+v9MhfjklShqKwgj8+39iZC5/odvqUjqUCQ:J7r+v9itLqdvqUqI

Entry address:
0x1704

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, AC, 10, 5D, 00, A1, 9F, 10, 5D, 00, C1, E0, 02, A3, A3, 10, 5D, 00, 52, 6A, 00, E8, 85, E1, 1C, 00, 8B, D0, E8, B2, 14, 17, 00, 5A, E8, F0, 13, 17, 00, E8, 03, 16, 17, 00, 6A, 00, E8, E4, 31, 17, 00, 59, 68, 48, 10, 5D, 00, 6A, 00, E8, 5F, E1, 1C, 00, A3, A7, 10, 5D, 00, 6A, 00, E9, DF, D4, 17, 00, E9, 16, 32, 17, 00, 33, C0, A0, 91, 10, 5D, 00, C3, A1, A7, 10, 5D, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, EC, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
6.4858

Code size:
1.8 MB (1,900,544 bytes)

Service
Display name:
MayaSvc

Service name:
SvcMaya

Description:
mi5 management service system

Type:
Win32OwnProcess, InteractiveProcess


Scan negqedtua.exe - Powered by Reason Core Security